Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
CVE-2026-12793 preview

CVE-2026-12793

GitHubrootxn/cve-2026-12793

Python PoC for CVE-2026-12793 in JetFormBuilder <= 3.6.2: unauthenticated privilege escalation leading to plugin upload and remote code execution,…

exploitationpayload-generationpenetration-testing+5
9 days ago
CVE-2025-24813 preview

CVE-2025-24813

GitHube5dfdd568a75282b712b6d93a7a18e12/cve-2025-24813

Python PoC exploiting CVE-2025-24813, an Apache Tomcat partial PUT deserialization RCE. Auto-detects vulnerable variants, supports blind command…

exploitationpayload-generationpenetration-testing+5
10 days ago
CVE-2025-32432 preview

CVE-2025-32432

GitHube5dfdd568a75282b712b6d93a7a18e12/cve-2025-32432

Python exploit for CVE-2025-32432, an unauthenticated RCE in Craft CMS via Yii2 __class injection, with command execution and reverse shell support.

exploitationpayload-generationpenetration-testing+4
10 days ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubthekawix/cve-2026-41940

Generates detection artifacts to verify cPanel/WHM authentication bypass vulnerability (CVE-2026-41940) and tests targets for exposure.

authenticationexploitationpenetration-testing+2
14 months ago
CVE-2026-0740 preview

CVE-2026-0740

GitHubxshadow-here/cve-2026-0740

Automated mass exploiter for CVE-2026-0740, an unauthenticated arbitrary file upload in Ninja Forms File Uploads plugin, enabling remote code…

exploitationpayload-generationpenetration-testing+3
35 months ago
CVE-2026-11112-XXE-via-SVG-Image-Upload preview

CVE-2026-11112-XXE-via-SVG-Image-Upload

GitHubgeorge0papasotiriou/cve-2026-11112-xxe-via-svg-image-upload

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

exploitationpayload-generationpenetration-testing+3
1 month ago
loxs-optimized preview

loxs-optimized

GitHubmomika233/loxs-optimized

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

payload-generationpenetration-testingscripting-automation+3
451 year ago
cve-2024-4367-poc preview

cve-2024-4367-poc

GitHubanomalousvectors/cve-2024-4367-poc

POC for PDF JS' CVE-2024-4367 vuln

exploitationpayload-generationvulnerability-analysis+1
21 year ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubjenderal92/cve-2026-49049

Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed…

exploitationpayload-generationpenetration-testing+4
1 month ago
CSRF-exploit-generator preview

CSRF-exploit-generator

GitHubjenderal92/csrf-exploit-generator

The CSRF Exploit Generator allows users to generate a CSRF exploit form with configurable parameters.

payload-generationpenetration-testingweb-application-exploitation+1
3 months ago
CVE-2019-10475 preview

CVE-2019-10475

GitHubvesche/cve-2019-10475

Reflected XSS proof-of-concept exploit for Jenkins build-metrics plugin CVE-2019-10475, with a Python weaponization script for generating malicious…

exploitationpayload-generationpenetration-testing+3
134 years ago
watchTowr-vs-Netscaler-CVE-2026-8451 preview

watchTowr-vs-Netscaler-CVE-2026-8451

GitHubwatchtowrlabs/watchtowr-vs-netscaler-cve-2026-8451

Python exploit tool for CVE-2026-8451 Citrix Netscaler memory overread vulnerability. Generates detection artifacts by leaking memory from target…

exploitationinformation-gatheringmemory-forensics+3
132 months ago
CVE-2025-7340 preview

CVE-2025-7340

GitHubnxploited/cve-2025-7340

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
71 year ago
CVE-2025-2807 preview

CVE-2025-2807

GitHubnxploited/cve-2025-2807

Wordpress - Motors Plugin <= 1.4.64 - Arbitrary Plugin Installation Vulnerability

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2024-8743-PoC preview

CVE-2024-8743-PoC

GitHubsiunam321/cve-2024-8743-poc

Proof-of-Concept script for WordPress plugin Bit File Manager version <= 6.5.7 Authenticated (Subscriber+) Limited JavaScript File Upload…

exploitationpayload-generationpenetration-testing+3
21 year ago
CVE-2024-52380-Exploit preview

CVE-2024-52380-Exploit

GitHubnxploited/cve-2024-52380-exploit

Picsmize plugin for WordPress is vulnerable to arbitrary file uploads.

exploitationpayload-generationpenetration-testing+3
31 year ago
CVE-2023-1545-POC-python preview

CVE-2023-1545-POC-python

GitHubsternstundes/cve-2023-1545-poc-python

CVE-2023-1545-POC with python

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2022-44268-fixed-PoC preview

CVE-2022-44268-fixed-PoC

GitHubcygnusx-26/cve-2022-44268-fixed-poc

Python PoC for CVE-2022-44268 that embeds arbitrary file contents into PNG images via ImageMagick, with extraction support for exiftool.

exploitationpayload-generationvulnerability-analysis+1
2 years ago
Previous123Next